An AI-powered autonomous attacker found a bug in Snowflake's code, which was inadvertently introduced by another AI coding assistant, and exploited it to extract credentials without human intervention.
Key Insights
The bug was introduced by GitHub Copilot Autofix, an AI coding assistant, and allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner. Fortunately, the vulnerability was discovered and fixed through Snowflake's bug bounty program, and the company has confirmed that there was no unauthorized access.










